There are 2 open security issues in trixie.
There are 2 open security issues in sid.
There are 2 open security issues in forky.
There are 2 open security issues in bullseye.
There are 2 open security issues in bookworm.
commit 35c88147e6b78a9a9efee7ab114da21e9940770b
Author: Thomas Goirand <zigo@debian.org>
Date: Thu Jun 4 23:57:25 2026 +0200
* OSSN-0098: Mistral workflow execution context exposes Keystone auth token.
Applied upstream patch: "Strip sensitive info from workflow execution
context" (Closes: #1138849).
commit 0cd57c9021442604456bc10bece13d28ef2dab80
Author: Thomas Goirand <zigo@debian.org>
Date: Mon May 25 17:07:47 2026 +0200
* CVE-2026-41283: Mistral policy enforcement bypass allows unauthorized
public resource creation and arbitrary code execution. Applied upstream
patches:
- Restrict publicize policies to admin only
- Remove unnecessary expect_errors=True from policy tests
- Add code_sources publicize policy and enforcement
- Restrict code_sources and dynamic_actions policies to
- Add dynamic_actions publicize policy and enforcement
- Add workbooks publicize policy and enforcement
- Add cron_triggers publicize policy and enforcement
- Add environments publicize policy and enforcement
Among the 2 debian patches available in version 22.0.0-1 of the package, we noticed the following issues: